A4 Refereed article in a conference publication

Patient Privacy in Differentially Private Diagnostic Models;




AuthorsJärv, Priit; Pahikkala, Tapio; Airola, Antti

EditorsSivagnanam, Amutheezan; Slamanig, Daniel

Conference nameInternational Workshop on Security and Privacy Analytics

Publication year2026

Book title IWSPA '26 : Proceedings of the 12th ACM International Workshop on Security and Privacy Analytics

First page 10

Last page15

ISBN979-8-4007-2609-5

DOIhttps://doi.org/10.1145/3806007.3810963

Publication's open availability at the time of reportingOpen Access

Publication channel's open availability Open Access publication channel

Web address https://doi.org/10.1145/3806007.3810963

Self-archived copy’s web addresshttps://research.utu.fi/converis/portal/detail/Publication/526899103

Self-archived copy's licenceCC BY

Self-archived copy's versionPublisher`s PDF


Abstract

Differential privacy gives a theoretical guarantee against inferring the presence of a patient in the training data of a model. Patients can have multiple data records that are used as separate training inputs, but to apply differential privacy we must view the contribution of a patient as a single privacy unit. The main approaches are user level privacy that uses all records of the patient as the privacy unit, group privacy which simplifies computation by allowing each patient to have at most k records, and sample level privacy that requires each patient to contribute one record. Of these, sample level privacy is well supported by efficient deep learning libraries and can be adapted to group privacy. User level differential privacy in the medical domain remains poorly supported by software and, as a consequence, unexplored. We compare these three approaches in experiments with cardiovascular disease and melanoma datasets. We found that in case most patients contribute only a single data record, sample level privacy suffices. With all patients contributing multiple records, user level privacy performed best, because it avoids the limitations of the alternative approaches: restricting the number of examples per patient, or inaccurately assuming all patients have the same number of records in privacy accounting.


Downloadable publication

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.




Funding information in the publication
This work was supported by Research Council of Finland (grant 358868).


Last updated on 03/08/2026 10:46:24 AM